Splunk Search

How to format text extracted from a lookup?

ChrisCLewis
Communicator

Good afternoon,

I have text in a lookup.csv that has hard returns in it, for example:

This is the reason why the sun is hot:
reason 1.
reason 2.
reason 3.

But the result from the lookup turns the hard returns into spaces turning it into a single long sentence, for example:

This is the reason why the sun is hot: reason 1. reason 2. reason 3.

Is there a way to keep the hard returns (special characters in the CSV) or to put them in post lookup?

Many thanks for your time.

0 Karma

to4kawa
Ultra Champion
...
| append [|inputlookup lookup.csv]

and stats etc...

0 Karma

dsctm3
Path Finder

Is it possible your lookup is using Windows text format on a Splunk instance installed on *nix?

If so, consider using the dos2unix command on the lookup file. (You may need to install if from yum/apt)

0 Karma

ChrisCLewis
Communicator

The value of the lookup is being sent to a token if that makes things easier / more difficult

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...